Categories: Payment system news

The Recent LastPass hack showcases Web2’s security limitations… Here’s what needs to change

Popular password management service LastPass revealed in a December 23 statement that it had been on the receiving end of a major hack last August. As a result, miscreants were able to make their way into several encrypted passwords, which could potentially be cracked through a technique called ‘brute force guessing,’ giving them access to sensitive consumer data.

When the incident initially came to light, a representative for LastPass tried to brush off the matter, stating that the attacker could only obtain peripheral technical information and not any private customer data. However, after a lengthy investigation into the matter, it was discovered that the hacker had used the info to gain access to an employee’s device, which then provided the individual(s) access to a plethora of customer data stored in a cloud storage system.

Due to this, unencrypted client metadata was revealed to the attacker, including employer names, end-user names, billing addresses, email addresses, telephone numbers, and IP addresses of customers who had accessed LastPass. Some customers’ encrypted vaults containing website passwords were also stolen.

Enter Web3

The exploitation of password managers such as LastPass has triggered a longstanding claim among Web3 developers that the traditional username and password login systems are not entirely secure and, therefore, should be replaced by blockchain-based data privacy systems.

To elaborate, advocates for Web3 security systems have repeatedly noted that traditional password-based login systems are vulnerable since they rely on hashed passcodes stored on cloud servers. If these hashes are breached, they can be decoded, and a single stolen password can compromise all accounts that use the same password.

In this regard, Web3 applications like ShareRing offer an alternative solution allowing users to access a decentralized platform that changes how individuals’ data — such as passwords — is shared across various online applications. The offering allows users to come up with their personal decentralized identities (DID), giving them complete control over their data.

To elaborate, ShareRing’s upcoming new feature within its popular ShareRing Vault module allows people to store usernames and passwords without any risk. In fact, all of the data stored in this ‘Password Manager’ is directly encrypted to the user’s ShareRing Vault private key instead of being stored on the cloud. As a result, it is accessible only to the ShareRing ID holder. Providing his thoughts on the LastPass hack, ShareRing CEO Tim Bos opined:

“The company has tried convincing customers that their login information is safe. Security experts disagree. An article by security researcher Wladimir Palant criticizes the company for lack of transparency. He points out the company has long-ignored calls to encrypt data such as URLs, meaning it is now difficult to trust the firm going forward. There are numerous security issues with cloud-based password managers such as LastPass. One of the most significant issues is where users’ encryption keys are stored and how well the firm secures this environment.”

Looking Ahead

While it is easy to criticize projects like LastPass, the fact of the matter remains that password managers have become extremely important in today’s day and age. This is because they allow users to remember extremely strong and unique passwords for every login detail that they may have.

However, with issues of password theft and other similar data breaches on the rise, it is important to harness the power of newer Web3 solutions that are able to keep consumer information absolutely safe thanks to their non-local design/operational frameworks. To this point, ShareRing’s password manager works across web2 and web3 applications while leveraging decentralized storage to keep its users’ information 100% secure. 

Therefore, as we head into a future driven by Web3 technologies, it is of utmost importance that individuals across the globe continue to educate themselves about the downsides of storing their sensitive data on centralized servers, thus allowing them to harness the potential of the blockchain ecosystem truly.

superadmin

Recent Posts

Ripple Intensifies RLUSD Treasury Activity As 15 Million Tokens Vanish from Supply

Ripple has burned another 15 million RLUSD as large treasury transactions continue to move the…

2 hours ago

Multi-Asset Trading Venue Monochrome Exchange Launches IEO of Its Native Token, $MCR

Monochrome Exchange, a multi-asset trading platform, has announced the Initial Exchange Offering (IEO) of its…

6 hours ago

XRP Whales Are On Fire—Binance Records 6-Month High As Whales Reawaken

XRP whales have recorded a major feat this September, as whale inflows on Binance have…

1 day ago

Robert Kiyosaki Warns of Looming Capital Market Crash as Bitcoin ETFs Stand Out; Here’s What’s Happening

Capital markets may see difficult times ahead, a warning to global investors. That is according…

1 day ago

Cardano’s Pogun to Unlock $1.6 Trillion Idle in Bitcoin DeFi Liquidity, Hoskinson Reveals How

One of the key challenges facing BTC users is Bitcoin’s DeFi idle liquidity. The good…

2 days ago

Legendary Investor Paul Barron Says SEC’s Tokenized-Stock Exemption Will Make Solana ‘Big Winners’ of Crypto-TradFi

As competition in the tokenized stock market shifts from simple issuance to real-world utility, prominent…

2 days ago